Citrix NetScaler Exploits Turn Edge Appliances Into Root-Level Network Tunnels
Citrix confirms active NetScaler exploits CVE-2026-88771 and CVE-2026-88772 enabling root access, web shells and network tunneling.
Illustrative image generated with AI
Citrix has confirmed active exploitation of two pre-authentication vulnerabilities in NetScaler ADC and NetScaler Gateway. The flaws, CVE-2026-88771 and CVE-2026-88772, allow attackers to compromise unmitigated appliances without valid credentials.
The attacks go beyond initial code execution. Investigators observed hidden PHP web shells, altered web-server configurations, persistent root access, credential theft, and tunneling from exposed NetScaler devices into internal networks.
Both vulnerabilities have been in the US Cybersecurity and Infrastructure Security Agency’s Known Exploited Vulnerabilities catalog since September 27, 2026. The federal remediation deadline is September 30, 2026.
Two exploited flaws affect the same NetScaler releases
CVE-2026-88771 is an improper input-validation vulnerability, categorized as CWE-20. It permits an unauthenticated remote attacker to execute arbitrary commands.
The NVD assigns it a CVSS v3 score of 9.8 and the vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVE-2026-88772 is a memory-safety flaw categorized as CWE-119, covering operations performed outside a memory buffer’s valid boundaries. It can cause remote code execution or denial of service, with the exploitable path involving DTLS.
Its NVD score is 8.1, with the vector:
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
A separate report gives CVE-2026-88772 a score of 9.5. The discrepancy does not change its operational significance: Citrix has confirmed exploitation, and successful attacks can achieve root-level shellcode execution.
The affected version thresholds listed for both vulnerabilities are:
| Product | Affected versions |
|---|---|
| NetScaler ADC | Earlier than 14.1-73.37 |
| NetScaler ADC | Earlier than 13.1-64.23 |
| NetScaler ADC FIPS | Earlier than 14.1-73.37 FIPS |
| NetScaler ADC FIPS and NDcPP | Earlier than 13.1.37.279 FIPS and NDcPP |
| NetScaler Gateway | Earlier than 14.1-73.37 |
| NetScaler Gateway | Earlier than 13.1-64.23 |
The NVD product summary also identifies NetScaler Application Delivery Controller and NetScaler Gateway releases below 13.1-64.23. Administrators should install the latest Citrix security updates rather than relying solely on version-string comparisons.
Malformed DTLS fragments trigger a large memory overwrite
The better-documented flaw, CVE-2026-88772, arises from inconsistent handling of fragmented DTLS handshake messages.
NetScaler trusts a fragment’s fragment_length field even when it conflicts with the total handshake length. In the example analyzed by watchTowr researcher Sina Kheirkhah, the complete message declares a length of 120 bytes, while every fragment claims to contain only one byte.
An attacker can submit fragments covering offsets 0 through 119. Once all offsets are present, NetScaler considers the handshake complete and begins reassembly.
The amount of buffered data, however, can be far larger than the declared message. Each 1,459-byte packet is stored in a NetScaler Buffer, or NSB. The packets are subsequently copied into a 35,840-byte scratch buffer.
The vulnerable implementation does not confirm that each incoming packet will fit before performing the next write. After 120 records, the declared handshake appears complete, while the associated NSB chain contains roughly 174 KB. Reassembling that chain causes an out-of-bounds write.
According to the technical reporting on CVE-2026-88772, the overflow can redirect execution to attacker-controlled shellcode. The exploit path uses mprotect() to bypass NX memory protections and obtain root-level execution.
Mandiant’s telemetry supports a similar conclusion: specially constructed or fragmented record headers corrupt heap boundaries in the NetScaler Packet Processing Engine, or NSPPE, enabling shellcode execution on the underlying FreeBSD system. Exploitation may also cause NSPPE to terminate unexpectedly, making unexplained packet-engine crashes a useful hunting signal.
Detailed exploitation mechanics for CVE-2026-88771 have not been publicly described. What is known is that it requires no authentication and can execute arbitrary commands.
Attackers concealed web shells behind ordinary file requests
GreyNoise detected an attempted attack against a NetScaler Gateway on September 24, 2026, three days before Citrix publicly disclosed the vulnerabilities. The attempt originated from 149.104.78.141.
The activity sought to modify /bin/sh for root-shell access and install a password-protected PHP web shell at:
/var/netscaler/logon/LogonPoint/custom/.ctxs.receiver
The attackers also attempted to alter /etc/httpd.conf. Their objective was to make requests for apparently harmless CSS resources, including receiver.min.css, invoke the concealed PHP file.
Other intrusions used comparable camouflage. Mandiant found web shells stored as .deb files in directories normally used for NetScaler client software. Attackers configured those package files to execute as PHP.
In additional cases, malicious code was hidden in .sig files. Changes to the web-server configuration mapped requests for .ico images under /vpn/media/ to the PHP payloads.
The shells used functions such as shell_exec() and eval() to run commands. Some returned fake HTTP 404 responses while executing those commands, allowing malicious traffic to resemble failed requests for ordinary static content.
Initial exploitation provided root privileges, but commands launched through the NetScaler web server would ordinarily inherit a less privileged account. Attackers addressed that limitation by setting the setuid bit on /bin/sh, preserving a path back to root execution. They also rebooted appliances or restarted the web server to activate configuration changes.
WHIPSHOT and SLAPSHOT open paths into internal networks
Mandiant identified two previously undocumented malware families during the intrusions.
WHIPSHOT is a PHP web shell disguised as a Debian package and placed in the NetScaler VPN scripts directory. It extracts Base64-encoded data from HTTP headers and acts as an HTTP-facing proxy for a second implant.
WHIPSHOT can determine whether that implant is running. It can also extract embedded Python payloads and launch them in the background.
SLAPSHOT is the Python-based tunneling component. It receives instructions through WHIPSHOT and can connect to internal hosts, exchange data, and close sessions. It may terminate itself after a period of inactivity.
In at least one intrusion, attackers used this tunnel for manual internal reconnaissance and credential theft. That capability makes appliance compromise particularly dangerous: NetScaler systems are commonly Internet-facing but also occupy a network position from which internal services may be reachable.
Traditional endpoint detection may not cover these appliances. A successful exploit can therefore create a difficult-to-monitor bridge around perimeter controls.
Mandiant believes attacks began in at least early September and affected organizations in North America and Europe. Victims included government, financial services, education, legal, and professional-services entities. The identity of the attackers has not been disclosed.
Hunting should continue after patches are installed
Installing Citrix’s latest security updates blocks the known vulnerable paths, but it does not remove artifacts left by an earlier compromise. Operators should inspect appliances for persistence and configuration manipulation.
High-value checks include:
- The
.ctxs.receiverweb shell or unexpected files under NetScaler web directories. - Unauthorized
AliasorAliasMatchdirectives inhttpd.conf. - PHP handlers assigned to
.deb,.sig,.ico, or other unusual extensions. - PHP code embedded in files presented as packages, signatures, images, or stylesheets.
- Setuid root permissions applied to
/bin/sh. - Changes to
/bin/shownership, mode, or contents. /tmp/.uxdportor/tmp/.uxdlock, which are associated with SLAPSHOT.- Python processes launched through
nohup. - Python commands or files containing large Base64-encoded payloads.
- Unexpected NSPPE crashes.
- Suspicious command activity paired with HTTP 404 responses.
- Connections involving
149.104.78.141.
GreyNoise has not released the complete exploit. Absence of traffic from the identified address therefore cannot establish that an appliance is clean.
Organizations should preserve relevant logs and configuration files before rebuilding or restarting suspected systems where operationally possible. Credentials accessible through a compromised appliance should also be treated as potentially exposed.
DTLS mitigation covers only one of the two vulnerabilities
Where immediate patching is impossible, disabling DTLS can reduce exposure to CVE-2026-88772. Organizations that do not require DTLS can also block inbound UDP traffic on port 443 upstream of the appliance.
Neither measure addresses CVE-2026-88771. Updating to a fixed NetScaler release is the available action that covers both exploited vulnerabilities.
CISA requires federal agencies to apply vendor mitigations, follow BOD 26-04 risk-based patching guidance, and meet its forensic-triage requirements by September 30, 2026. For cloud services, agencies must follow the applicable BOD 26-04 guidance or discontinue use when mitigations are unavailable. They must also evaluate each asset’s Internet exposure.
These entries are not isolated within Citrix’s recent KEV history. CVE-2026-19490 entered the catalog on September 9, 2026, and CVE-2026-8452 followed on August 26, 2026.
For CVE-2026-88771 and CVE-2026-88772, exploitation is already established. Patching should be paired with forensic review, because the observed operators installed durable access mechanisms and used compromised appliances to reach systems behind the network perimeter.
Sources
This article is an original reworking based on the sources below.
CVEs covered in this article
- CVE-2026-88771Critical9.8Improper input validation vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; Gateway: before 14.1-73.37 and before 13.1-64.23 leading to an unauthenticated a
- CVE-2026-88772High8.1Vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; Gateway: before 14.1-73.37 and before 13.1-64.23 leading to Remote Code Execution or Denial of Service




